6 Layers of Brute Force Defense
Each layer catches what the one above it might miss.
Incoming brute force login attempts
1Edge WAFCloudflare · blocks attacks at 300+ edge locations
2Rate limitingCaps login attempts per IP · edge + application
3Two-factor authenticationMakes a guessed password useless
4Disable XML-RPCCloses the system.multicall backdoor
5Strong passwords & usernamesKills dictionary attacks and the "admin" target
6Custom login URLHides wp-login.php from bot traffic
✓
Your origin serverStays fast and focused on real visitors